CVE-2026-64823 | home-assistant Home Assistant Core up to 2026.5.3 Shelly integration async_get_media_image thumb cross site scripting

SecurityVulns

A vulnerability classified as problematic was found in home-assistant Home Assistant Core up to 2026.5.3. Affected is the function async_get_media_image of the component Shelly integration. The manipulation of the argument thumb results in cross site scripting.

This vulnerability is known as CVE-2026-64823. It is possible to launch the attack remotely. No exploit is available.VulDB Recent EntriesRead More